A new vulnerability in Citrix NetScaler is already being actively exploited, according to security researchers. Attackers are systematically scanning for vulnerable systems and exfiltrating data.
What Is Known
The vulnerability affects Citrix NetScaler ADC and Gateway — products used in many enterprises as VPN gateways, load balancers and application delivery controllers. Researchers suspect it may involve multiple related vulnerabilities.
Exploitation occurred within days of disclosure. This is consistent with the trend of recent years: the time between disclosure and exploitation is getting shorter.
Recommendation
Administrators should immediately verify whether their NetScaler instances are patched. Citrix has provided patches. Systems that were exposed before the patch should be investigated for compromise — patching alone does not close an already established access.
NetScaler is a perennial target in security incidents. The combination of widespread deployment, internet exposure and delayed patching makes these products preferred targets.
Source: The Register (30.03.2026), Citrix Security Advisory.